Legal
Privacy Policy
Last updated
Three commitments first: we do not sell your personal information as a subscriber, we do not train models on it and do not authorize anyone else to, and every company that processes it is named on this page. Beyond that, this policy is short because the product is short — CUSignals analyzes institutions, not people. Two groups are covered here: subscribers, whose data is the little needed to run an account, and the credit-union officers whose business contact details some plans carry. If you are the second, section 12 is written for you and you do not need an account to use it.
Who we are
CUSignals is operated by Infinidatum LLC, a Connecticut limited liability company, which is the controller of the personal information described here. This policy covers the CUSignals website, dashboard and API. For any privacy question or request, write to admin@infinidatum.net.
Our commitments
- We do not sell your personal information as a subscriber, and we do not disclose it to anyone to use for their own marketing. If instead you have reached this page because your name appears in the product as an officer of a credit union, section 12 is written for you and gives you a way to see, correct or remove it.
- We do not train models on your data and do not authorize any provider to. The models this product runs are scorecards over institution-level financials; they are not trained on subscriber behavior, and nothing you do in the dashboard becomes training data.
- We analyze institutions, not people. The Service holds no data about the members or customers of any institution, and our Terms forbid you from sending us any.
- We collect the minimum. An account needs a name, an email and a password. That is very nearly the whole of it.
- Your data is processed in the United States, by United States companies subject to United States law.
What we collect
- Account information — your name, work email address and organization when you register, and a securely hashed password. We never store a password in readable form. If you sign in with Google instead, we receive the email address and name on that Google account and no password at all.
- Subscription and usage activity — your plan and territory, the pages and signals you open, the filters and exports you run, and API request logs. We use this to operate your entitlement, to enforce plan scope, to prevent abuse, and to keep an audit trail of who accessed what.
- Payment information — handled entirely by Stripe. We receive confirmation that a purchase completed, the plan it was for, and the billing email. We do not receive or store your card number.
- Device and log data — IP address, browser user-agent and timestamps, retained for security, rate limiting and diagnostics.
- Free-trial records — when you start a free trial we store, with the subscription at Stripe, a one-way keyed hash of the network address the request came from and of a random identifier your browser keeps for this purpose. This is how the trial is limited to one per organization. We do not store the address or build a profile from it, the hashes cannot be reversed into either value, and they are used for nothing but answering whether a trial has already been taken. Clearing site data for this domain removes the browser identifier. See the Cookie Notice.
- Analytics — aggregate page-view counts via Google Analytics 4, only if you allow it. Nothing is requested from Google until you do, and a Global Privacy Control signal from your browser is honored automatically as a standing refusal. See the Cookie Notice, where the choice can be changed at any time.
- Sign-up funnel counts — so we can tell how many people start registering and stop, we record on our own servers which step of the sign-up path was reached, the page it happened on, the host that referred you and any campaign tag in the link you followed. Against each of those we store a one-way keyed hash of the network address the request came from — the same technique as the free-trial records above — so that two steps can be recognized as one visit. The address itself is never stored, the hash cannot be reversed into it, and it is used for nothing but this count. No cookie is set, nothing is stored on your device, nothing is sent to a third party, and no email address is attached until you type one into our own form. This is a first-party operational record of the same kind as a web server log, so it is not part of the analytics choice above; it is deleted after 90 days.
- Sales enquiries — when you use a “Contact sales” form we store what you typed into it: your email address, and the name, organization and message if you gave them, along with which plan you were looking at and the campaign tag on the link that brought you. It is kept so a person can answer you and so we can see later which enquiries we failed to answer. This is the one place on the site where we store free text you have written, and it is deliberate — you typed it into a form that says it goes to our sales team. It is never sent to an analytics service and never attached to the sign-up funnel counts described above, which record only that an enquiry happened.
- Correspondence — anything you email us, kept so we can answer it and refer back to it.
How we use it
- to provide, operate and improve the Service and to provision your access;
- to authenticate you and to enforce the scope of your subscription;
- to take payment and to manage renewals and cancellations;
- to secure the Service, detect abuse and enforce our Terms;
- to answer your messages and send service notices about your account; and
- to comply with legal obligations.
Where a legal basis is required, ours are performance of our contract with you, our legitimate interest in operating and securing the Service, your consent — which is what analytics runs on, and nothing else does — and compliance with law. We do not use your information to make any decision with a legal or similarly significant effect on you, and we do not profile you.
Who processes it (sub-processors)
We name every company that handles your personal information on our behalf, because a promise about where data goes is worth exactly as much as the list behind it. Each is a United States company, is contractually bound to process data only to provide its service to us, and is not permitted to use it for its own purposes or to train models on it.
- Vercel — application hosting and edge delivery for the website, dashboard and API.
- Neon — the managed PostgreSQL database holding accounts, entitlements and the signal panel.
- Stripe — payment processing and subscription billing. Stripe is a PCI-DSS Level 1 service provider and is the system of record for card data, which never reaches us.
- Google — Google Analytics 4 for aggregate usage measurement on the public pages, and Google Sign-In where your organization uses it to authenticate.
This list changes as the Service changes; when it does, we change this page and move the revision date. Some of these providers run globally distributed networks, so an individual request may be served from infrastructure outside the United States that a United States company owns and controls. Where that happens the provider remains a United States company subject to United States law. We do not otherwise route your data abroad.
When we disclose information
We disclose personal information only:
- to the sub-processors named above, under contract;
- to comply with law, legal process, or a lawful government request;
- to establish or exercise our legal rights, or to protect the rights, safety and security of subscribers, the public or the operator named in section 1; and
- in connection with a merger, acquisition or sale of assets, in which case this policy continues to apply to the information transferred.
We do not sell subscriber personal information and we do not share it for cross-context behavioral advertising. Officer business contact details carried in the product are addressed separately in section 12, which gives the people named in them a rights and opt-out channel that does not require an account.
How long we keep it
We keep account and entitlement records for as long as your subscription is active and for as long afterwards as we need them to meet legal, tax and audit obligations, to resolve disputes and to enforce our agreements. Request logs and device data are kept for a rolling operational window and then discarded. Billing records are kept for the period tax law requires. You can ask us to delete your account at any time and we will, subject to those retention obligations.
Security and breach notification
We protect your information with encryption in transit, hashed passwords, signed HttpOnly session cookies, scoped API keys, least-privilege access to production and rate limiting. The Security page describes the controls in more detail and explains how to report a vulnerability. No system is perfectly secure and we do not claim otherwise.
If a breach affects your personal information we will notify you and the applicable regulators as required by law, without undue delay. As a Connecticut company our baseline is that state’s breach-notification statute (Conn. Gen. Stat. § 36a-701b): notice to affected residents no later than 60 days after discovery, and notice to the Connecticut Attorney General no later than the time those residents are notified. Where your own state sets a shorter deadline or requires more, we follow your state’s law instead.
Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to obtain a portable copy, to opt out of certain processing, and to withdraw a consent you previously gave. You will not be treated differently for exercising any of them.
To make a request, email admin@infinidatum.net from the address on your account, or tell us which account the request concerns so we can verify it. You may use an authorized agent. We respond within the time your law allows — generally 45 days under the CCPA/CPRA and the Connecticut Data Privacy Act, extendable once with notice. If we decline a request we will say why, and you may appeal by replying to our response or complain to your state attorney general.
California and other state privacy rights
If you are a California resident, the CCPA/CPRA gives you the right to know the categories and specific pieces of personal information we collect, to delete and correct it, to opt out of any sale or sharing, and to limit the use of sensitive personal information.
We do not sell or share subscriber personal information — your name, email, organization and account activity are never sold, never disclosed for anyone else’s marketing, and never shared for cross-context behavioral advertising, and we run no advertising tags. Officer business contact details are the one category where the question is genuinely open, because subscribers pay for access to a product that carries them; rather than argue the definition, we give the officers named in it the full set of rights, including opt-out, in section 12. We honor Global Privacy Control regardless, treating it as a standing refusal of analytics, and we do not collect sensitive personal information as the CCPA defines it, so the right to limit does not arise. Over the preceding twelve months we collected the categories listed in section 3 — identifiers, commercial information, and internet and network activity — from you and your device, used them for the business purposes in section 4, and disclosed them only to the sub-processors in section 5. Comparable rights under the Colorado, Connecticut, Virginia, Utah, Texas and other state privacy acts are honored on the same terms; use the same address.
Data about institutions is not personal data
The scores, ratios, rankings and matches the Service publishes describe credit unions as institutions. A credit union’s balance sheet is not personal information about anyone, and what it means is covered by the Disclaimer rather than by this policy. The one exception is the subject of the next section, and it is a real exception rather than a formality: some plans carry the name and business telephone number of a named officer, and a named officer is a person.
If your business contact details appear in the Service
Some plans include the name, title and business telephone number of a credit union’s senior officers, so that a subscriber can route an approach to the right desk. If you are one of those officers, this section is addressed to you, and it applies whether or not you have any other dealing with us.
What we hold, and where it came from. Your name, your role, and a business telephone number or business email at the institution you work for. We obtained it from institution-level records and affiliated business-data sources rather than from you, which is why you will not have heard from us before. We hold nothing about you personally — no home address, no personal contact details, no financial information about you, and nothing about you as a member or customer of any institution.
What it is used for. One purpose: identifying the right professional contact at an institution a subscriber is researching, for business-to-business outreach. It is not used to build a profile of you, it is not combined with anything about your private life, it feeds no score or ranking, and no automated decision is made about you. Subscribers receive it under terms permitting business outreach and nothing else, and their own obligations under applicable marketing and telemarketing law govern any contact they make.
Your rights, and how to use them. Depending on where you live you may have the right to know what we hold about you, to correct it, to delete it, to obtain a copy, and to opt out of its sale or sharing. You do not need an account with us to exercise any of them. Write to admin@infinidatum.net, naming yourself and your institution, and say what you want done. We verify that you are the person named — ordinarily by replying to the institution’s own published contact rather than to whatever address the request arrived from — and we act within the time your law allows, generally 45 days. If you ask to be removed, we remove you at the next refresh and keep only the minimum record needed to ensure you are not silently added back. There is no charge, and we will not treat you differently for asking.
An institution may make this request on behalf of its officers as a group, and the same address handles it.
Children
The Service is a business product, is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us information, tell us and we will delete it.
Changes, and how to reach us
We may update this policy as the Service changes; material changes are reflected in the revision date at the top and, where they affect your rights, by email. For any privacy question, access request or deletion request, write to admin@infinidatum.net.